The FCA Mills Review: What AI Delegation Means for Regulated Firms


On 6 July 2026 the Financial Conduct Authority (FCA) published the Mills Review, an independent review of how artificial intelligence could reshape retail financial services by 2030 and beyond. The Review creates no new obligations. It makes seven recommendations to the FCA Board, and its central conclusion is that the existing framework, including the Consumer Duty, the Senior Managers Regime and operational resilience requirements, remains sound and will not be replaced by a separate AI rulebook.
What the Review does do is tell firms where the FCA expects those regimes to come under strain as AI moves from assisting people to acting for them. It identifies operational resilience and the regulatory perimeter as the first pressure points, with the Senior Managers Regime and the Consumer Duty holding until firms delegate more decision-making. Firms with retail customers should read it as an indication of what supervisors will ask about over the next few years, and should check they can already evidence where AI sits inside their customer journeys and controls.
What the Mills Review Is, and What It Does Not Do
The Review was commissioned by the FCA Board and led by Sheldon Mills, an FCA executive director. The FCA has catalogued it as a corporate document rather than a consultation paper or a policy statement. Its recommendations are addressed to the FCA Board and Executive, not to firms. Nothing in it amends the Handbook, and it is not guidance on which firms can rely. The FCA has not published a formal response to the recommendations at the time of writing.
The Review runs to 147 pages with seven annexes. It draws on 140 written responses to an Engagement Paper that opened on 26 January 2026 and closed on 24 February 2026, alongside meetings, panels and roundtables with firms, trade bodies, consumer groups, technology providers and international regulators. It is also supported by commissioned consumer research, an online survey of 5,026 UK retail financial services consumers carried out by Yonder Consulting with fieldwork between 21 and 29 April 2026, together with focus groups and a comparison of international approaches.
The subject matter is retail financial services. The firms with the clearest interest are retail banks and building societies, consumer credit and debt firms, mortgage lenders and intermediaries, retail investment and wealth managers, pensions providers and advisers, retail protection and general insurance firms and intermediaries, and payments and e-money firms. Firms operating only in wholesale markets have less direct read-across, although the Review's analysis of concentration among model and infrastructure providers is relevant to any firm that depends on third-party technology.
The FCA's Key Findings
The Review organises its analysis around a single idea: the regulatory question is not what the technology can do, but how much of the decision the human still makes.
The Autonomy Spectrum, and Why the FCA Uses It
The Review sets out a five-level spectrum describing the changing role of the human as AI takes on more. There are five roles on the spectrum:
Operator. The human uses AI as a tool to understand, analyse or complete a defined task.
Collaborator. The human and the AI system plan and act together.
Consultant. The AI system compares options and recommends actions, and the human decides.
Approver. The AI system prepares or initiates actions, and the human authorises key steps.
Observer. The AI system acts continuously within boundaries set in advance, and the human monitors outcomes rather than deciding.
The Review is explicit that this is not a prediction that financial services will become fully autonomous, and that few use cases will travel the whole spectrum. Its value is in showing how risk changes as the human role changes. Early questions about accuracy and over-reliance give way to harder questions about consent, accountability and redress.
Where the Existing Regimes Come Under Strain
The Review maps five regimes against the spectrum and identifies the point at which each first comes under pressure. The order is not the one most firms expect:
Operational resilience shows increasing complexity from the earliest levels, as firms take on shared dependencies on a small number of providers, and reaches a pressure point at Approver.
The regulatory perimeter also shows complexity early, becomes an emerging pressure point at Consultant, and a potential framework mismatch at Observer.
The advice and guidance boundary comes under pressure at Approver, with a risk of regulatory arbitrage at Observer.
The Consumer Duty operates effectively to Consultant, becomes more complex at Approver, and reaches a pressure point at Observer.
The Senior Managers Regime operates effectively to Consultant, becomes more challenging at Approver, and reaches a pressure point at Observer, where meaningful human control is likely to be difficult to evidence.
The Review's own summary is that the framework needs progressive adaptation, not wholesale replacement
The Senior Managers Regime and Meaningful Human Control
The Review records that no firm argued the accountability model should change, and that firms consistently said responsibility should continue to rest with senior managers in regulated entities. It agrees that the Senior Managers Regime is robust where AI operates in the Operator, Collaborator and Consultant modes.
Its concern is narrower and more practical. Without clearer guidance, the opacity of more delegated AI operation, combined with factors such as model drift, could create a gap between the outcome of an AI-mediated decision and the ability to identify a responsible individual, or for that individual to exercise meaningful human control. Stakeholders asked for clearer guidance on what "reasonable steps" require where AI systems are involved. The Review notes that clearer expectations would give firms more confidence to adopt AI, rather than less.
The Consumer Duty in Continuous, AI-Mediated Journeys
The Review finds that the Consumer Duty applies straightforwardly where AI supports human decisions, and that firms can demonstrate good outcomes, consumer understanding and foreseeable harm using established methods.
The difficulty arises as journeys become dynamic, personalised and delegated. AI-enabled pricing may make it harder to distinguish benign personalisation from extraction of value. Dynamic journeys may make it harder to evidence that a consumer genuinely understood the product and the risk. Models may embed historic patterns of bias in ways that affect outcomes across consumer groups. At higher levels of autonomy, the Review suggests that one-off consent may prove insufficient where a system makes many small decisions over time, and that detriment could occur before a consumer is aware of it.
The Perimeter, the Advice Boundary and the Consumer Research
The Review's sharpest question is whether influence over consumers' financial decisions is moving outside the regulatory perimeter. General-purpose AI tools shape how consumers understand products, narrow options and act, in ways that can resemble guidance or advice without amounting to a regulated activity. The Review notes the resulting competitive asymmetry: regulated firms report being constrained from providing similar personalised support, while unregulated platforms may exert comparable influence without equivalent obligations.
The consumer research gives this some weight. Around a fifth of consumers said they were likely to use AI acting autonomously within pre-set goals, which the FCA equated to roughly 11 million UK adults. Around 26% agreed that tools such as ChatGPT provide reliable financial information or advice. Only 40% correctly identified that there is no formal route to recourse if something goes wrong after using a general-purpose AI service for financial advice, and 67% said they were concerned about a lack of protection if something goes wrong.
The Review recommends that the FCA conduct a review of the scale, nature and impact of general-purpose large language models outside the perimeter, and suggests this should be done within three to six months of the report. That points to roughly October 2026 to January 2027, although the FCA has not confirmed a timetable. The Review also notes that the same questions apply beyond investments, to debt management, savings, pensions and drawdown, and mortgages and home finance, and it references existing Handbook provisions including COBS 9 and 9A, MCOB 4 and 4A, CONC 8 and Perimeter Guidance at PERG 8.
Shared Dependencies and System-Wide Risk
The Review identifies a category of risk it says sits outside firm-level frameworks. Where many firms rely on the same model provider, an outage, security breach or degradation in model performance could affect all of them at once. Where firms use similar models for underwriting, pricing or recommendations, decision-making could become correlated, producing herding effects and a narrowing of consumer outcomes. Regulators may have limited visibility of that concentration until something goes wrong.
The Review notes that the Critical Third Parties regime is technology-agnostic and could capture major providers where HM Treasury's designation criteria are met, but that the regime complements rather than replaces firms' own responsibility for managing third-party risk. This matters to firms that do not think of themselves as AI adopters at all, because AI increasingly arrives inside products bought from existing suppliers.
What the Review Recommends the FCA Should Do
The Review makes seven priority recommendations for the FCA Board and Executive to consider. They are:
Secure and adapt the regulatory perimeter, beginning with a review of general-purpose large language models operating outside it.
Strengthen system-wide coordination and oversight, domestically and internationally.
Monitor the transition to autonomous models and adapt regulatory frameworks, including clarifying how the Consumer Duty and the Senior Managers Regime apply.
Scale up the FCA's AI Lab to assess AI models and systems used in financial services.
Enable the foundations for agentic finance, covering identity, mandates, control and liability for AI agents acting on a consumer's behalf.
Build and adopt an AI-enabled agentic supervisory model, with human supervisors retaining responsibility for judgement and intervention.
Develop a trusted public-interest AI-enabled financial capability service, free at the point of use.
Only the first carries an indicative timeframe. The others are directional, and the Review is clear that decisions on taking them forward rest with the FCA Board and Executive.
Key Themes for Firms
Three themes run through the document and are worth separating from the detail.
The first is that the burden falls on evidence rather than on new rules. The Review repeatedly frames the challenge as one of demonstrating outcomes, control and accountability, not of meeting a new standard. Firms that can already show how an AI-assisted decision was made, monitored and corrected are in a materially better position than those that cannot.
The second is that governance is treated as the practical constraint on adoption. The Review's findings on firm transformation state that AI governance and model risk management will become a critical capability by 2030, and it notes that governance frameworks operated by smaller firms will need to evolve alongside those of larger firms.
The third is that the most significant change is at system level rather than firm level. Concentration, correlated behaviour and shared points of failure are not problems any single firm can solve. Firms cannot fix them, but they can map their own dependencies and avoid being surprised by them.
What Should Firms Do Now
No firm is required to do anything as a result of the Mills Review. The proportionate response for most firms is a scoped review of where AI already sits in the business, rather than a new AI compliance framework. The following steps are drawn directly from the pressure points the Review identifies.
Map current AI use, including AI embedded in third-party systems the firm has not procured as AI, such as customer service platforms, fraud tools, underwriting engines and document processing.
Place each material use on the autonomy spectrum, so the firm can say plainly whether a human decides, authorises or simply observes.
Check that responsibility for AI-enabled processes is allocated to a named senior manager, and that the relevant Statement of Responsibilities and governance papers reflect it.
Test whether existing Consumer Duty outcomes evidence still works where AI shapes pricing, communications or support, particularly the consumer understanding and price and value outcomes.
Review third-party and outsourcing arrangements, including whether AI dependencies appear in important business services mapping and impact tolerances.
Bring AI-enabled processes into the compliance monitoring plan and into management information, so oversight is evidenced rather than assumed.
Provide proportionate training to first-line staff and to those exercising oversight, so that human review is a real control rather than a formality.
Document the firm's reasoning, including where it has concluded that a use case is low risk and no further action is needed.
Firms whose commercial models involve referral arrangements, paid placement or comparison and routing should also follow the perimeter review, since its findings could affect the boundary they operate against.
Compliance Angle's view is that the Review is best treated as a supervisory signal rather than a project. For most firms, a half-day mapping exercise and a short paper to the board or governing body will meet the point, and a wholesale governance rebuild is not warranted on the strength of a document that changes no rules. The firms most exposed are not the ones experimenting with AI, but the ones that cannot say where AI already sits in their processes.
Frequently Asked Questions
Does the Mills Review create new rules for FCA-regulated firms?
No. The Mills Review is an independent review commissioned by the FCA Board and published on 6 July 2026. It is not a consultation paper, a policy statement or guidance. It makes seven recommendations to the FCA Board and Executive, and it does not amend the FCA Handbook or create any new obligation for firms.
Which firms does the Mills Review apply to?
The Review is about retail financial services. Its findings are most relevant to retail banks and building societies, consumer credit and debt firms, mortgage lenders and intermediaries, retail investment and wealth managers, pensions providers and advisers, retail protection and insurance firms, and payments and e-money firms. Firms operating only in wholesale markets have less direct read-across, although the analysis of third-party and model concentration risk is still relevant.
Is the FCA planning to introduce AI-specific regulation?
The Review does not recommend a separate AI rulebook. It concludes that the existing outcomes-based framework, including the Consumer Duty, the Senior Managers Regime and operational resilience requirements, remains sound and should be clarified rather than replaced. Any change to the FCA's approach would follow the usual consultation process, and the FCA has not confirmed which recommendations it will take forward.
What does the Mills Review say about the Senior Managers Regime and AI?
It says the Senior Managers Regime remains robust where AI assists, collaborates with or advises human decision-makers, and that no firm argued the accountability model should change. It identifies a pressure point where AI operates with greater autonomy, because model opacity and model drift could make it harder to identify a responsible individual or to evidence meaningful human control. Stakeholders asked the FCA for clearer guidance on what reasonable steps require in that context.
What is the AI autonomy spectrum in the Mills Review?
It is a five-level framework describing the changing role of the human as AI takes on more: Operator, where AI is a tool; Collaborator, where human and AI work together; Consultant, where AI recommends and the human decides; Approver, where AI prepares actions the human authorises; and Observer, where AI acts within pre-set boundaries and the human monitors outcomes. The Review uses it to show how regulatory risk changes as delegation increases.
How Compliance Angle Can Help
Compliance Angle supports FCA-regulated firms and firms seeking authorisation with the practical work the Mills Review points towards, without turning a directional document into an unnecessary programme of change.
We can help with:
Governance and risk management reviews, including mapping where AI sits in the business and how oversight is exercised.
SM&CR support, covering allocation of responsibility for AI-enabled processes and evidencing reasonable steps.
Consumer Duty support, including whether existing outcomes monitoring still works where AI shapes pricing, communications or customer support. Our article on Consumer Duty outcomes monitoring covers the FCA's expectations in more detail.
Compliance frameworks and policies, including proportionate updates to existing policies rather than new standalone documents.
Ongoing compliance support and monitoring, bringing AI-enabled processes into the compliance monitoring plan and management information.
Compliance training for first-line staff and for those exercising human oversight of AI-assisted decisions.
Support is scaled to the firm's business model, permissions, size and regulatory risk. A small intermediary using an AI-assisted customer service tool needs a very different piece of work from a lender embedding models in underwriting decisions, and we scope accordingly.
To discuss how the Mills Review affects your firm, contact us at info@complianceangle.co.uk.
Source: The Mills Review: AI and the future of retail financial services, Financial Conduct Authority, 6 July 2026.


